INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Adobe Fixes Magento Zero-Day Exploited to Deploy Rust Backdoor
| 2026-09-08 13:34 CRITICAL HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE MALWARE & BOTNETS
Executive Summary
AI-generated
The incident data suggests a sophisticated cyber operation involving the exploitation of vulnerabilities in various software products, including Microsoft 365 and Windows Server. The attackers used tactics such as phishing, malware, and rootkit deployment to breach the systems of over 258 organizations. The use of invisible Unicode characters in phishing attacks further highlights the sophistication of the threat. The incident data also reveals a focus on targeted sectors, with cyber operations targeting industries like finance and healthcare.
Technical Mitigations AI-generated
* Use secure protocols: Ensure that all communication between your application and the server is encrypted using HTTPS (Hypertext Transfer Protocol Secure) or TLS (Transport Layer Security). This will prevent eavesdropping and tampering attacks.
* Keep software up-to-date: Regularly update your Adobe Commerce and Magento Open Source installation to ensure you have the latest security patches. Use a reputable source, such as the official website or a trusted security vendor, to stay informed about available updates.
* Implement secure coding practices: Follow best practices for secure coding, such as using input validation and sanitization, and avoiding common web application vulnerabilities like SQL injection and cross-site scripting (XSS).
* Use secure authentication mechanisms: Ensure that your authentication mechanism is secure by using strong passwords, multi-factor authentication, and validating user input carefully.
* Monitor system logs and perform regular security audits: Regularly review system logs to detect potential security incidents. Perform thorough security audits on your application and infrastructure to identify vulnerabilities and weaknesses.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
bi•••@bl•••.•••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
bi•••••.toulas
re•••••.magento
ad•••••.com
ww•••••.com
10•••••.jpg
10•••••.jpg
10•••••.jpg
10•••••.png
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
CVE-2026-75746CVE-2026-75746
CVE-2026-48273CVE-2026-48273
CVE-2026-75650CVE-2026-75650
CVE-2026-82004CVE-2026-82004
Target & Sectors
BENELUX
BENELUX
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
2016 August
Threat actors exploited a Magento zero-day vulnerability to gain unauthorized access and backdoor servers using Windows Server 2016 August updates.
Click on any entity below to view its context and source!
infrastructure
Windows
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
tactic
T1584.004 - Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
infrastructure
2016 Windows Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
August 2026
Adobe released a hotfix for its e-commerce products to address CVE-2026-75650, which exploits a zero-day vulnerability in Adobe Commerce versions 2.4.4 through 2.4.9 and Adobe Commerce B2B versions 1.3.3 through 1.5.3.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-75650
Adobe notes that the flaw impacts the following versions of its e-commerce products:
* Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
* Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
* Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch
The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.
infrastructure
2.4.4
Adobe notes that the flaw impacts the following versions of its e-commerce products:
* Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
* Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
* Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch
The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.
infrastructure
2.4.9
Adobe notes that the flaw impacts the following versions of its e-commerce products:
* Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
* Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
* Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch
The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.
infrastructure
1.3.3
Adobe notes that the flaw impacts the following versions of its e-commerce products:
* Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
* Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
* Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch
The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.
infrastructure
1.5.3
Adobe notes that the flaw impacts the following versions of its e-commerce products:
* Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
* Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
* Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch
The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.
infrastructure
2.4.6
Adobe notes that the flaw impacts the following versions of its e-commerce products:
* Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
* Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
* Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch
The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.
organisation
Magento Open Source
Adobe notes that the flaw impacts the following versions of its e-commerce products:
* Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
* Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
* Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch
The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.
organisation
OAuth
After installing the hotfix, administrators should enable maintenance mode, suspend cron jobs, and rotate all secrets, including administrator passwords, GraphQL integration tokens, OAuth client secrets, payment gateway API credentials, database credentials, SSH keys, and API keys.
organisation
API
After installing the hotfix, administrators should enable maintenance mode, suspend cron jobs, and rotate all secrets, including administrator passwords, GraphQL integration tokens, OAuth client secrets, payment gateway API credentials, database credentials, SSH keys, and API keys.
organisation
SSH
After installing the hotfix, administrators should enable maintenance mode, suspend cron jobs, and rotate all secrets, including administrator passwords, GraphQL integration tokens, OAuth client secrets, payment gateway API credentials, database credentials, SSH keys, and API keys.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation
EU CRA
Check your EU CRA readiness in 5 questions.
September 4, 2026
Threat actors used a zero-day exploit in Adobe's Adobe Photoshop software to target servers managed by the e-commerce development platform Magento.
Click on any entity below to view its context and source!
target_region
Netherlands
According to Netherlands-based Disrex, a Magento server managed by the e-commerce development platform is said to have been compromised 50 minutes after the first confirmed StyleSmuggler exploitation was reported on September 4, 2026, at 10:20 p.m. UTC.
organisation
Disrex
According to Netherlands-based Disrex, a Magento server managed by the e-commerce development platform is said to have been compromised 50 minutes after the first confirmed StyleSmuggler exploitation was reported on September 4, 2026, at 10:20 p.m. UTC.
general_metric
50 minutes
According to Netherlands-based Disrex, a Magento server managed by the e-commerce development platform is said to have been compromised 50 minutes after the first confirmed StyleSmuggler exploitation was reported on September 4, 2026, at 10:20 p.m. UTC.
vulnerability
CVE-2026-75650
The vulnerability, now tracked as
CVE-2026-75650
(CVSS score: 10.0), has been codenamed
StyleSmuggler
by Sansec, which discovered zero-day exploitation starting September 4, 2026.
organisation
StyleSmuggler
The vulnerability, now tracked as
CVE-2026-75650
(CVSS score: 10.0), has been codenamed
StyleSmuggler
by Sansec, which discovered zero-day exploitation starting September 4, 2026.
organisation
Sansec
The vulnerability, now tracked as
CVE-2026-75650
(CVSS score: 10.0), has been codenamed
StyleSmuggler
by Sansec, which discovered zero-day exploitation starting September 4, 2026.
at least September 4
Sansec discovered that the flaw has been exploited in attacks since at least September 4 to plant a backdoor on vulnerable websites.
Click on any entity below to view its context and source!
organisation
Sansec
E-commerce security company Sansec discovered that the flaw has been leveraged in attacks since at least September 4 to plant a backdoor on vulnerable websites.
September 7, 2026
Threat actors used IP addresses from China and Romania to exploit a critical Magento zero-day vulnerability.
Click on any entity below to view its context and source!
organisation
IP
Telemetry data from Previdian shows that
12 exploitation attempts
have been recorded against its honeypots since September 7, 2026, from two unique IP addresses from China and Romania.
target_region
China
Telemetry data from Previdian shows that
12 exploitation attempts
have been recorded against its honeypots since September 7, 2026, from two unique IP addresses from China and Romania.
target_region
Romania
Telemetry data from Previdian shows that
12 exploitation attempts
have been recorded against its honeypots since September 7, 2026, from two unique IP addresses from China and Romania.
general_metric
12 exploitation attempts
Telemetry data from Previdian shows that
12 exploitation attempts
have been recorded against its honeypots since September 7, 2026, from two unique IP addresses from China and Romania.
2026/09/07
Adobe fixed a StyleSmuggler zero-day exploit in Adobe Commerce and Magento with yesterday's security update.
Click on any entity below to view its context and source!
organisation
StyleSmuggler
In an update yesterday, Adobe pushed a security fix that addresses the StyleSmuggler vulnerability in Adobe Commerce and Magento.
September 8, 2026
Threat actors used a newly discovered Adobe vulnerability to exploit a critical Magento zero-day that allowed them to backdoor servers.
Click on any entity below to view its context and source!
general_metric
0 09:34 AM
Adobe fixes critical Magento zero-day exploited to backdoor servers
By
###### Bill Toulas
* September 8, 2026
* 09:34 AM
* 0
!
vulnerability
CVE-2026-75650
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 8, 2026,
added
CVE-2026-75650 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
attribution
Known Exploited
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 8, 2026,
added
CVE-2026-75650 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
tactic
T1588.006 - Vulnerabilities
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 8, 2026,
added
CVE-2026-75650 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
attribution
KEV
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 8, 2026,
added
CVE-2026-75650 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
attribution
Federal Civilian Executive Branch
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 8, 2026,
added
CVE-2026-75650 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
attribution
FCEB
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 8, 2026,
added
CVE-2026-75650 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
organisation
Network Time Protocol
The backdoor disguised its command-and-control (C2) host as a regular Network Time Protocol (NTP) server.
organisation
NTP
The backdoor disguised its command-and-control (C2) host as a regular Network Time Protocol (NTP) server.
Sep 08, 2026
Threat actors exploited a previously unknown critical vulnerability in Adobe's popular e-commerce platform Magento to gain unauthorized access and install a backdoor on targeted servers.
2003 - 2026
Threat actors used Adobe's software to exploit a critical Magento zero-day vulnerability and backdoor servers.
Click on any entity below to view its context and source!
organisation
Social & Feeds
* Advertising
* Write for BleepingComputer
* Social & Feeds
* Changelog
Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure
Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved
[]( "Back to Top")
2.4.6-2026-aug
Adobe fixes critical Magento zero-day exploited to backdoor servers.
Click on any entity below to view its context and source!
general_metric
2026 Blue Report
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.9-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.8-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.7-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.6-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.5-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.4.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
repo.magento
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
VULN-39341-composer-patches.zip
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
1.3.4-2026-aug and
The threat actors exploited a critical Magento zero-day vulnerability in Adobe Commerce and B2B products.
Click on any entity below to view its context and source!
general_metric
2026 Blue Report
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.9-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.8-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.7-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.6-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.5-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.4.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
repo.magento
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
VULN-39341-composer-patches.zip
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
2.4.4-2026-aug
Adobe released hotfix patches for affected versions of Adobe Commerce and B2B, as well as Magento Open Source.
Click on any entity below to view its context and source!
general_metric
2026 Blue Report
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.9-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.8-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.7-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.6-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.5-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.4.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
repo.magento
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
VULN-39341-composer-patches.zip
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
2.4.5-2026-aug
Adobe fixes critical Magento zero-day exploited to backdoor servers.
Click on any entity below to view its context and source!
general_metric
2026 Blue Report
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.9-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.8-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.7-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.6-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.5-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.4.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
repo.magento
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
VULN-39341-composer-patches.zip
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
2.4.7-2026-aug and earlier
Adobe fixes critical Magento zero-day exploited to backdoor servers.
Click on any entity below to view its context and source!
general_metric
2026 Blue Report
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.9-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.8-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.7-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.6-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.5-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.4.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
repo.magento
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
VULN-39341-composer-patches.zip
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
2.4.6-2026-aug and earlier
Threat actors exploited a critical Magento zero-day vulnerability in Adobe Commerce and B2B products.
Click on any entity below to view its context and source!
general_metric
2026 Blue Report
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.9-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.8-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.7-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.6-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.5-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.4.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
repo.magento
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
VULN-39341-composer-patches.zip
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
2.4.9-2026-aug
Adobe fixes critical Magento zero-day exploited to backdoor servers.
Click on any entity below to view its context and source!
general_metric
2026 Blue Report
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.9-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.8-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.7-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.6-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.5-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.4.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
repo.magento
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
VULN-39341-composer-patches.zip
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
1.5.2-2026-aug and
The threat actors exploited a critical Magento zero-day vulnerability in Adobe Commerce and B2B products.
Click on any entity below to view its context and source!
general_metric
2026 Blue Report
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.9-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.8-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.7-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.6-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.5-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
2.4.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.5.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.4.2-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.4-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
infrastructure
1.3.3-2026
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
repo.magento
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
observable
VULN-39341-composer-patches.zip
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
2026/09/08
Adobe released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.
Click on any entity below to view its context and source!
infrastructure
Linux
[](
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
Get the report
### Related Articles:
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
N-able patches max severity N-central flaw amid ongoing attacks
Critical Elementor Pro flaw exploited to take over WordPress sites
* Actively Exploited
*
The development comes days after the Dutch e-commerce security company
revealed
that threat actors are exploiting CVE-2026-75650 to deploy a Rust-based Linux backdoor that connects to an external server and awaits further instructions.
organisation
infosec news
[](
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
organisation
APM
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
organisation
Hackers
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
organisation
WordPress
Get the report
### Related Articles:
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
N-able patches max severity N-central flaw amid ongoing attacks
Critical Elementor Pro flaw exploited to take over WordPress sites
* Actively Exploited
*
infrastructure
Microsoft 365
[Image 39: Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
BigBear Microsoft 365
[Image 39: Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
MFA
[Image 39: Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
victims
258 organizations
[Image 39: Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
Unicode
[Image 41: Phishing Attackers conceal phishing lures using invisible Unicode characters](
S ponsor Posts
* !
infrastructure
Windows
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
[Image 14: How to start Windows in Safe Mode How to start Windows in Safe Mode](
* !
[Image 16: How to show hidden files in Windows 7 How to show hidden files in Windows 7](
* !
[Image 17: How to see hidden files in Windows How to see hidden files in Windows](
* Webinars
* Downloads
* Latest
* Most Downloaded
* !
organisation
Stack Protection
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
organisation
Windows Registry
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
organisation
the Windows Registry
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
organisation
Adobe Commerce
Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce.
"This update resolves a critical vulnerability that could result in arbitrary code execution," Adobe
said
, adding it's "aware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants.
organisation
PHP
In an update to its original report, Sansec says that a second attacker with unrelated tooling has been observed exploiting CVE-2026-75650 to deploy a 485-byte PHP web shell.
"
At its core, the flaw abuses Magento's template system through PHP code injection to generate a "Payment Transaction Failed Reminder" email, triggering code execution in the process.
data_breach
485 byte PHP web shell
In an update to its original report, Sansec says that a second attacker with unrelated tooling has been observed exploiting CVE-2026-75650 to deploy a 485-byte PHP web shell.
organisation
CVE-2026-75650
"This update resolves a critical vulnerability that could result in arbitrary code execution," Adobe
said
, adding it's "aware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants.
organisation
Magento Open Source
Ravie Lakshmanan
Sep 08, 2026
Vulnerability / Web Security
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.
organisation
Vulnerability / Web Security
Ravie Lakshmanan
Sep 08, 2026
Vulnerability / Web Security
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.
organisation
Adobe Commerce
Ravie Lakshmanan
Sep 08, 2026
Vulnerability / Web Security
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.
organisation
Magento
"
At its core, the flaw abuses Magento's template system through PHP code injection to generate a "Payment Transaction Failed Reminder" email, triggering code execution in the process.
Adobe fixes critical Magento zero-day exploited to backdoor servers.
organisation
Adobe
[Image 3: Adobe fixes critical Magento zero-day exploited to backdoor servers Adobe fixes critical Magento zero-day exploited to backdoor servers](
* !
In tandem, Adobe has also
released
patches for more than 170 vulnerabilities across its products, including CVE-2026-82004 (CVSS score: 10.0), an operating system command injection flaw in Campaign Classic leading to arbitrary code execution.
infrastructure
10.0
In tandem, Adobe has also
released
patches for more than 170 vulnerabilities across its products, including CVE-2026-82004 (CVSS score: 10.0), an operating system command injection flaw in Campaign Classic leading to arbitrary code execution.
threat_actor
ShinyHunters
[Image 4: ShinyHunters hackers claim breach of Florida ShinyHunters hackers claim breach of Florida "DAVID" DMV database](
* !
organisation
DMV
[Image 4: ShinyHunters hackers claim breach of Florida ShinyHunters hackers claim breach of Florida "DAVID" DMV database](
* !
organisation
DoppelCart
[Image 7: DoppelCart fraud network uses 119,000 fake shops to steal credit cards DoppelCart fraud network uses 119,000 fake shops to steal credit cards](
* !
organisation
IP
[Image 31: How to change IP address.jpg) How to change IP address](
* !
organisation
safely.jpg
Access the dark web safely.jpg)
organisation
ThreatLocker
[Image 34: ThreatLocker](
* Home
* News
*
organisation
CTI
[Image 44: CTI Starter Kit + 2026 SANS CTI Survey CTI Starter Kit + 2026 SANS CTI Survey](
* !
organisation
Upcoming Webinar
[Image 37: ThreatLocker](
Upcoming Webinar
!
organisation
Astra
[Image 40: ChatGPT ChatGPT Astra is now rolling out to $20 Plus subscription](
* !
financial
$20 $ subscription
[Image 40: ChatGPT ChatGPT Astra is now rolling out to $20 Plus subscription](
* !
organisation
Freestar.com
Submitting...
SUBMIT
Freestar.com
!
organisation
CVE-2026-75746
Also patched by Adobe are two critical vulnerabilities in ColdFusion CVE-2026-48273, CVSS score: 9.9, and CVE-2026-75746, CVSS score: 9.1) that could result in arbitrary code execution.
organisation
ColdFusion CVE-2026-48273
Also patched by Adobe are two critical vulnerabilities in ColdFusion CVE-2026-48273, CVSS score: 9.9, and CVE-2026-75746, CVSS score: 9.1) that could result in arbitrary code execution.
organisation
CVSS
Also patched by Adobe are two critical vulnerabilities in ColdFusion CVE-2026-48273, CVSS score: 9.9, and CVE-2026-75746, CVSS score: 9.1) that could result in arbitrary code execution.
organisation
Deploy Rust Backdoor
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell.
September 2026
Threat actors exploited a critical Adobe Magento zero-day vulnerability to gain unauthorized access and backdoor servers.
Click on any entity below to view its context and source!
organisation
Microsoft
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
general_metric
966 flaws
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
general_metric
2 days
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
September 11, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-75650 to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply the fix by September 11, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-75650
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 8, 2026,
added
CVE-2026-75650 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
attribution
Known Exploited
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 8, 2026,
added
CVE-2026-75650 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
tactic
T1588.006 - Vulnerabilities
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 8, 2026,
added
CVE-2026-75650 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
attribution
KEV
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 8, 2026,
added
CVE-2026-75650 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
attribution
Federal Civilian Executive Branch
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 8, 2026,
added
CVE-2026-75650 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
attribution
FCEB
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 8, 2026,
added
CVE-2026-75650 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
[](
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
Get the report
### Related Articles:
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
N-able patches max severity N-central flaw amid ongoing attacks
Critical Elementor Pro flaw exploited to take over WordPress sites
* Actively Exploited
*
The development comes days after the Dutch e-commerce security company
revealed
that threat actors are exploiting CVE-2026-75650 to deploy a Rust-based Linux backdoor that connects to an external server and awaits further instructions.
Metrics
infrastructure
Microsoft 365
Affected Product
[Image 39: Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
Metrics
victims
258
Organizations
[Image 39: Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
Metrics
infrastructure
Windows
Affected Product
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
[Image 14: How to start Windows in Safe Mode How to start Windows in Safe Mode](
* !
[Image 16: How to show hidden files in Windows 7 How to show hidden files in Windows 7](
* !
[Image 17: How to see hidden files in Windows How to see hidden files in Windows](
* Webinars
* Downloads
* Latest
* Most Downloaded
* !
Metrics
infrastructure
2,016
Windows Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
Metrics
infrastructure
2.4.4
Software Version
Adobe notes that the flaw impacts the following versions of its e-commerce products:
* Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
* Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
* Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch
The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.
Metrics
infrastructure
2.4.9
Software Version
Adobe notes that the flaw impacts the following versions of its e-commerce products:
* Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
* Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
* Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch
The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.
Metrics
infrastructure
1.3.3
Software Version
Adobe notes that the flaw impacts the following versions of its e-commerce products:
* Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
* Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
* Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch
The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.
Metrics
infrastructure
1.5.3
Software Version
Adobe notes that the flaw impacts the following versions of its e-commerce products:
* Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
* Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
* Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch
The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.
Metrics
infrastructure
2.4.6
Software Version
Adobe notes that the flaw impacts the following versions of its e-commerce products:
* Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
* Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
* Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch
The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.
Metrics
data_breach
485
Byte Php Web Shell
In an update to its original report, Sansec says that a second attacker with unrelated tooling has been observed exploiting CVE-2026-75650 to deploy a 485-byte PHP web shell.
Metrics
financial
20
$ Subscription
[Image 40: ChatGPT ChatGPT Astra is now rolling out to $20 Plus subscription](
* !
Metrics
infrastructure
2.4.9-2026
Software Version
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
Metrics
infrastructure
2.4.8-2026
Software Version
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
Metrics
infrastructure
2.4.7-2026
Software Version
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
Metrics
infrastructure
2.4.6-2026
Software Version
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
Metrics
infrastructure
2.4.5-2026
Software Version
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
Metrics
infrastructure
2.4.4-2026
Software Version
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
Metrics
infrastructure
1.5.3-2026
Software Version
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
Metrics
infrastructure
1.5.2-2026
Software Version
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
Metrics
infrastructure
1.4.2-2026
Software Version
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
Metrics
infrastructure
1.3.4-2026
Software Version
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
Metrics
infrastructure
1.3.3-2026
Software Version
The shortcoming affects the following versions -
Adobe Commerce
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
2.4.5-2026-aug and earlier
2.4.4-2026-aug and earlier
Adobe Commerce B2B
1.5.3-2026-aug and earlier
1.5.2-2026-aug and earlier
1.4.2-2026-aug and earlier
1.3.4-2026-aug and earlier
1.3.3-2026-aug and earlier
Magento Open Source
2.4.9-2026-aug and earlier
2.4.8-2026-aug and earlier
2.4.7-2026-aug and earlier
2.4.6-2026-aug and earlier
Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip
"To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe
said
.
Metrics
infrastructure
10.0
Software Version
In tandem, Adobe has also
released
patches for more than 170 vulnerabilities across its products, including CVE-2026-82004 (CVSS score: 10.0), an operating system command injection flaw in Campaign Classic leading to arbitrary code execution.
Intelligence Sources
The Hacker News
2026-09-08
BleepingComputer
2026-09-08
Adobe fixes critical Magento zero-day exploited to backdoor servers
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-09T07:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
43x
organisation
Identified Entity
infosec news
entity
20x
timeline
Temporal Reference
September 8, 2026
date
17x
infrastructure
Software Version
2.4.4
version
8x
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
5x
attribution
Attributing Entity
Update
The U.S. Cybersecurity and Infrastructure Security Agency
authority
4x
target region
Target Country
United States
country
4x
tactic
Cyber Operation Type
Data Breach
tactic
4x
vulnerability
Exploited CVE
CVE-2026-75650
cve
3x
infrastructure
Affected Product
Linux
software
2x
general metric
Windows
11
windows
Contextual Telemetry
Context Block
21 METRICS
industry
Targeted Sector
Media
sector
general metric
Microsoft
365
microsoft
victims
Organizations
258
organizations
infrastructure
Windows Server
2,016
windows server
data breach
Byte Php Web Shell
485
byte php web shell
general metric
Flaws
966
flaws
general metric
Days
2
days
threat actor
APT Group
ShinyHunters
actor
general metric
Fake Shops
119,000
fake shops
general metric
09:34 Am
0
09:34 am
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
financial
$ Subscription
20
$ subscription
general metric
Questions
5
questions
general metric
%
37
%
general metric
Minutes
50
minutes
general metric
Exploitation Attempts
12
exploitation attempts
general metric
Vulnerabilities
170
vulnerabilities
general metric
Score
10
score
general metric
Cvss Score
9
cvss score
general metric
Sep
8
sep
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.